XK0-006 Security Practice Question
A Linux administrator is hardening a server that runs a custom application. The security team requires that the system enforce password complexity and account lockout policies. The administrator decides to use PAM. Which TWO modules should be added to the appropriate PAM configuration files to enforce these requirements? (Choose two.)
⚠ Common exam trap
The trap here is selecting the deprecated pam_tally2.so for lockout instead of the current pam_faillock.so, which is now the recommended module on modern Linux distributions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
pam_faillock.so
To enforce password complexity, pam_pwquality.so is the standard module, checking password strength against configured criteria. For account lockout, pam_faillock.so is the modern replacement for pam_tally2.so, tracking failed attempts and locking accounts after a threshold. Together, they meet the security team's requirements when placed in the correct PAM stacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
pam_unix.so
Why it's wrong here
pam_unix.so handles traditional Unix password authentication and shadow password updates. It does not enforce complexity rules or lockout policies by itself. While it is a core module for authentication, it cannot fulfill the specific requirements of complexity and lockout without additional modules.
- ✓
pam_faillock.so
Why this is correct
pam_faillock.so provides account lockout after a specified number of failed authentication attempts. It is configured in the auth and account stacks of PAM configuration files, such as /etc/pam.d/system-auth and /etc/pam.d/password-auth. This module satisfies the account lockout requirement and is the current standard on Red Hat and similar distributions.
- ✗
pam_tally2.so
Why it's wrong here
pam_tally2.so is a legacy module for counting failed login attempts and locking accounts. While it can enforce lockout policies, it has been deprecated in favor of pam_faillock.so on modern distributions. Using it may work but is not the recommended current module, and it does not handle password complexity.
- ✗
pam_limits.so
Why it's wrong here
pam_limits.so sets resource limits for user sessions, such as maximum number of processes or open files. It does not deal with password complexity or account lockout. It is used in the session stack and is unrelated to the security requirements described.
- ✓
pam_pwquality.so
Why this is correct
pam_pwquality.so enforces password quality rules such as minimum length, character classes, and dictionary checks. It is typically placed in the password stack of /etc/pam.d/common-password or /etc/pam.d/system-auth. This module directly addresses the password complexity requirement by rejecting weak passwords during password changes.
Go deeper
Related to this question
Learn chapter
Networking Fundamentals and Configuration
Key term
PAM
Privileged Access Management (PAM) is a security framework that controls, monitors, and audits access to critical systems and accounts with elevated permissions.
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.